Deck Help Center

WebRTC and IP leaks

WebRTC can hand a site your real address even through a working proxy. Here is what LoginDeck does about it, and how to prove it.

Updated Β· 4 min read

On this page

A proxy carries the browser's web traffic. WebRTC β€” the API behind video calls β€” does not use it: it sends small UDP packets to a STUN server to discover the addresses it could be reached on, and SOCKS proxies do not carry UDP. Those addresses then sit in the connection candidates, where any page can read them in a few lines of JavaScript.

That is why a profile can pass an IP-location test and still be telling sites your home address. It beats every other location signal, because it is the machine's own answer about itself.

πŸ“‘ What LoginDeck does#

The WebRTC control is on the profile editor's Advanced tab and has three positions.

SettingWhat happens
Based on proxy (default)The browser refuses to send UDP the proxy cannot carry, so your own address is never gathered. It then reports the candidate set a real Chrome behind a home router would show β€” local names rather than raw addresses, plus the proxy's own exit address, which the site already knows from the connection.
DisabledNothing is gathered. Candidate collection finishes empty.
RealStock behaviour: whatever your machine says, including your real address.

Leave it on Based on proxy. It is the setting that closes the leak while still looking like an ordinary browser β€” a browser where WebRTC exists but produces nothing at all is itself slightly unusual.

With no proxy, "Based on proxy" behaves like "Real"

If the profile has no proxy, the site sees your address anyway, so there is nothing to protect and stock WebRTC is the coherent answer.

Disabled is what the Crypto profile type sets, on the argument that a leaked local address matters more at an exchange than looking perfectly ordinary. It is also a reasonable choice for any account where you never need calls or screen sharing.

πŸ”€ Proxies that change address#

When the exit can move on its own β€” a bound phone, or a saved proxy that has a Change IP link β€” LoginDeck does not offer the exit address as a candidate at all, because the address it had at launch may not be the address in use ten minutes later, and a candidate that disagrees with the connection is worse than none. Those profiles report the shape a Chrome on a network where UDP is blocked shows.

🚰 The other ways an address leaks#

  • A dead proxy. LoginDeck never falls back to a direct connection. If the proxy stops answering, the browser still opens β€” pointed at that proxy β€” and pages simply fail to load. That is deliberate: an account quietly logging in from your own address is much worse than a browser that will not load a page. A profile whose saved proxy has been deleted refuses to launch outright.
  • A clock that does not match. Not an address leak, but it puts you in a different country just as effectively. See Timezone and language follow your proxy.
  • A proxy that is not where you think it is. Check it: Check proxies and see where they exit.
  • Other privacy extensions. Anti-fingerprinting extensions installed inside a profile fight with the engine's own values and usually produce contradictions. Do not stack them.

βœ… Proving it#

Run a fingerprint check on the profile (row β‹― β†’ Fingerprint check). Two rows answer this question:

  • Exit address, under Location β€” it fails when the browser is not going out through the proxy at all.
  • WebRTC addresses, under Automation and leaks β€” it fails if a public address that is not the proxy exit reached the page, or if raw local addresses reached it instead of local names. It passes when only local names were offered, or when the only public candidate is the exit itself.

For a second opinion, use Open a detector… on the same screen and pick BrowserLeaks WebRTC. It opens the real profile, through its real proxy, at a site whose whole job is this one question.

ℹ️ Good to know#

  • Firefox profiles ignore this setting. The Firefox engine handles WebRTC itself.
  • Changing the setting takes effect at the next launch; stop and restart the profile.
  • The Real position exists for testing. If a profile has ever run on it against an account that matters, treat that account as having seen your address.